CVE-2021-20683: XSS
Published Mar 26, 2021
·Updated
Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.
Affected Software
1 affected component
baserCMS BaserCMS<4.4.5
Remediation
Patch Available
Event History
Mar 26, 2021
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-20683?
CVE-2021-20683 is an improper neutralization vulnerability in the blog article editing function of baserCMS versions prior to 4.4.5.
2
How does CVE-2021-20683 affect baserCMS?
CVE-2021-20683 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors in the blog article editing function of baserCMS.
3
What versions of baserCMS are affected by CVE-2021-20683?
BaserCMS versions prior to 4.4.5 are affected by CVE-2021-20683.
4
What is the severity of CVE-2021-20683?
CVE-2021-20683 has a severity rating of medium with a CVSS score of 5.4.
5
How can I fix CVE-2021-20683 in baserCMS?
To fix CVE-2021-20683, update baserCMS to version 4.4.5 or higher.